Secure Multi-Cloud Network Virtualization

被引:10
作者
Alaluna, Max [1 ]
Vial, Eric [1 ]
Neves, Nuno [1 ]
Ramos, Fernando M., V [1 ]
机构
[1] Univ Lisbon, Dept Informat, Fac Ciencias, LASIGE, Edificio C6 Piso 3, P-1749016 Lisbon, Portugal
基金
欧盟地平线“2020”;
关键词
Network virtualization; Network embedding; Multi-cloud platform;
D O I
10.1016/j.comnet.2019.06.004
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Existing network virtualization systems share a few characteristics, namely they target one data center of a single operator and only offer traditional networking services. As such, their support for critical applications that need to be deployed across multiple trust domains, while enforcing diverse security requirements, is limited. This paper enhances the state-of-the-art by presenting a multi-cloud network virtualization system, allowing the provision of virtual networks of containers. Our solution enables a provider to enrich its network substrate with public and private cloud-based resources, increasing flexibility and the range of supplied services. One challenging aspect that we tackle is the embedding of virtual network requests to the substrate infrastructure, as existing work is unfit to a modern data center context, scales poorly or does not consider the security of virtual resources. We propose a scalable heuristic that considers security as a first-class citizen and is specifically tailored to a hybrid multi-cloud domain. We evaluate our algorithm with large-scale simulations that consider realistic network topologies and our prototype in a substrate composed of one private data center and two public clouds. The system scales well for networks of thousands of switches employing diverse topologies and improves on the virtual network acceptance ratio, provider revenue, and embedding delays. Our results show that the acceptance ratios are less than 1% from the optimal and that the system can provision a 10 thousand container virtual network in approximately 2 minutes. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:45 / 60
页数:16
相关论文
共 47 条
  • [1] Al-Shabibi Ali., 2014, P 3 WORKSHOP HOT TOP, P25, DOI DOI 10.1145/2620728.2620741
  • [2] Alaluna M., ABS170301313 CORR
  • [3] [Anonymous], 2017, RIGHTSCALE STATE CLO
  • [4] [Anonymous], P ACM SIGCOMM 2012 C
  • [5] [Anonymous], 2018, 15 USENIX S NETW SYS
  • [6] Towards Predictable Datacenter Networks
    Ballani, Hitesh
    Costa, Paolo
    Karagiannis, Thomas
    Rowstron, Ant
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2011, 41 (04) : 242 - 253
  • [7] Bays L. R., 2013, P 8 INT C NETW SERV, P378
  • [8] Ben-Yehuda M., 2010, 9 S OPERATING SYSTEM, V10, P423
  • [9] Bessani A., 2014, USENIX ATC 14, P169
  • [10] DEPSKY: Dependable and Secure Storage in a Cloud-of-Clouds
    Bessani, Alysson
    Correia, Miguel
    Quaresma, Bruno
    Andre, Fernando
    Sousa, Paulo
    [J]. ACM TRANSACTIONS ON STORAGE, 2013, 9 (04)